ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

WordPress.org now auto-blocks risky plugin releases with AI-powered security review

infoToolsimportance 58
What's new: WordPress.org introduced an automated, AI-powered security review that gates every plugin and theme release: updates are held in a six-hour cooldown (in effect since June 5, 2026), analyzed by multiple AI models plus Jetpack Scan, and automatically blocked from the update API if they exceed the risk threshold. The policy was adopted after a July 28, 2026 backdoor in a plugin with ~20,000 active…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Every WordPress.org plugin and theme release is now held in a six-hour cooldown, scored by multiple AI models plus Jetpack Scan, and automatically blocked from distribution if high-risk — a gate introduced after a July 28, 2026 backdoor incident.

The WordPress Official Plugin Repository Team has launched an automated security review for plugin releases. Since June 5, 2026, all releases — including one-click dashboard updates — are held for a six-hour cooldown while multiple AI models and Jetpack Scan cross-check the code changes and produce a consolidated risk score designed to reduce false positives. Releases scoring above the blocking threshold are automatically withheld from the WordPress.org update API. The change follows a July 28, 2026 incident in which a backdoor was committed to a release of a plugin with roughly 20,000 active installations; the backdoor was detected during the cooldown and never delivered to users, and the Plugins Team withheld the release and closed the plugin for downloads 26 minutes after Wordfence notified them. Blocked authors receive an email with the findings and can either publish a corrected release scoring below the threshold — described as usually faster — or appeal to the Plugins Team. The team notes the scores measure risk exposure rather than developer intent and asks authors to report false positives.

  • Every WordPress.org plugin and theme release now passes an automated security review and receives a risk score before distribution.
  • All releases, including one-click dashboard updates, have been held in a six-hour cooldown since June 5, 2026.
  • The review combines multiple AI models with Jetpack Scan to cross-check release changes and reduce false positives.
  • Releases exceeding the risk threshold are automatically blocked from the WordPress.org update API until resolved.
  • The change followed a July 28, 2026 backdoor committed to a release of a plugin with roughly 20,000 active installations; it was caught during the cooldown and never delivered.
  • The Plugins Team withheld the release and closed the plugin for downloads 26 minutes after Wordfence notified them.
  • Blocked authors receive an email with the findings and can publish a corrected release scoring below the blocking threshold (usually faster) or appeal to the Plugins Team.
  • Risk scores measure risk exposure, not developer intent; the team requests false-positive reports.

Coverage timeline

  1. · 6d ago
    Help Net Security· 55
    WordPress adds automated security checks to block risky plugin releases

    WordPress.org now automatically security-reviews every plugin release and blocks high-risk updates before distribution to millions of sites.

  2. · 6d ago
    Cyber Security News· 52
    WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

    WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.

  3. · 5d ago
    GBHackers· 58
    WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

    WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.